Or you just allow traffic from Vlan2 to you wireguard Server IP on Rules : Vlan2 in incoming direction above the block rule